Skip to content
Fidkeep
FeaturesHow it works
Sign inStart for free

Fidkeep legal

Privacy Policy

This policy explains how Fidkeep collects, uses, shares, and protects personal data when you use our website and review-management service.

Effective date: 31 July 2026

On this page

  1. Scope and who we are
  2. Data we collect
  3. How we use data
  4. Google user data
  5. AI processing
  6. Sharing and processors
  7. Cookies and storage
  8. Retention and deletion
  9. Security
  10. Your rights
  11. International transfers
  12. Children
  13. Changes and contact

Fidkeep is designed for business users who manage Google Business Profile locations and customer reviews. This policy covers both the public website at fidkeep.com and the authenticated Fidkeep application.

1. Scope and who we are

Fidkeep (“Fidkeep,” “we,” “us,” or “our”) provides tools for collecting Google Business Profile reviews in one workspace, preparing AI-assisted reply drafts, publishing replies, coordinating team access, and reviewing location-level reports.

For the personal data described in this policy, Fidkeep acts as the data controller unless we process data solely on behalf of a business customer. A business customer may also be a controller of reviewer, employee, and invitee data placed in its workspace. Questions can be sent to [email protected].

2. Data we collect

Account and identity data

We collect your name, email address, profile image when supplied by an identity provider, email-verification state, account role, and account timestamps. If you use email and password, we store a protected password representation rather than the plain-text password. If you sign in with Google, we receive the basic profile information Google makes available for authentication.

Authentication and security data

We process session identifiers, session expiry, IP address, browser or device user-agent information, verification and password-reset records, linked sign-in methods, security events, and redacted audit records. Google OAuth access and refresh tokens, token expiry, and granted scopes are stored so authorized background synchronization can continue.

Google Business Profile data

When you authorize the https://www.googleapis.com/auth/business.manage scope, we may retrieve and store:

  • Business Profile account identifiers, resource names, display names, account type, role, and verification state.
  • Location identifiers, title, storefront address, category, place identifier, profile image, and synchronization timestamps.
  • Review identifiers, reviewer display name and profile image, star rating, review text, attached media references, creation and update times, and current reply or moderation state.
  • Owner reply text, publication state, update times, and any Google policy status returned for a reply.

Workspace and service content

We process selected locations, team memberships and roles, invitation email addresses, location access, reply language and tone, preferred or prohibited phrases, signatures, reply examples, AI instructions, automatic-reply settings, report recipients, draft replies, publishing actions, generated reports, feedback, and support communications.

Operations and usage records

We record service operations such as synchronization, draft generation, publication, report delivery, errors, timestamps, quota usage, model and token statistics, delivery state, and related technical identifiers. We may also receive information you provide when requesting support.

3. How and why we use data

We use the data above to:

  • create and secure accounts, sessions, and sign-in methods;
  • connect authorized Google accounts and synchronize selected business accounts, locations, reviews, media references, and reply states;
  • prepare, save, edit, and publish review replies at your direction, including automatic replies when an authorized user enables that setting;
  • configure location-specific brand language and generate review and performance reports;
  • support workspace roles, invitations, location access, service plans, and usage limits;
  • send verification, security, invitation, report, and service messages;
  • prevent abuse, investigate errors, enforce permissions, maintain reliability, and protect Fidkeep and its users; and
  • comply with legal obligations, resolve disputes, and enforce our terms.

Depending on the context and applicable law, we rely on performance of our agreement with you, your consent or Google authorization, our legitimate interests in operating and securing the service, and compliance with legal obligations. Where consent is the basis, you may withdraw it without affecting processing already performed.

4. Google user data and Limited Use

Fidkeep’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

We request Google Business Profile access only to provide user-facing review-management functions: listing accounts and locations, retrieving reviews and related public business data, showing reply status, and publishing or updating replies that you direct Fidkeep to send. We do not sell Google user data, use it for targeted advertising, transfer it to advertising platforms or data brokers, or allow humans to read it except when you consent, it is necessary for security or support, or applicable law requires it.

OAuth tokens are encrypted at rest and are used to obtain authorized access from Google. You can revoke Fidkeep’s Google access through your Google Account permissions. Revoking access stops new synchronization and publication but does not automatically erase data already stored in your workspace. To request deletion of stored Google-derived data, contact [email protected].

5. AI-assisted processing

Fidkeep uses OpenRouter to obtain AI-generated reply drafts, location configuration suggestions, report narratives, and structured product feedback issue reports. Depending on the feature, prompts may include the business or location name and category, review rating and text, reviewer display name, selected review facts, location language and tone, preferred or prohibited phrases, signatures, example replies, instructions supplied by an authorized user, feedback text, selected feedback category and sentiment, the current page path and title, and the active business location.

OpenRouter and the selected model provider process this information to return an output. Fidkeep records operational information such as the selected model, generated text or report, token usage, cost, status, and provider request identifiers. AI output can be inaccurate or unsuitable. Users should review outputs before publication; if automatic replies are enabled, the workspace owner remains responsible for that configuration and the resulting publications.

6. Sharing and service providers

We disclose data only as needed for the purposes in this policy:

  • Google: for authentication, Business Profile synchronization, access checks, and publishing or updating replies.
  • OpenRouter and model providers: to process prompts and generate the AI-assisted content described above.
  • Linear: to receive AI-structured product feedback issue reports together with the original feedback comment, the submitting user's name, email address, and internal user identifier for internal product planning, follow-up, and resolution.
  • Resend: to deliver account verification, password reset, invitation, security, report, and other service emails.
  • Hosting and infrastructure providers: to operate databases, cache, messaging, backups, networking, logging, and service availability.
  • Authorized workspace members: according to assigned location roles and permissions.
  • Authorities or transaction parties: when required by law, necessary to protect rights and safety, or connected with a merger, financing, acquisition, or sale of assets subject to appropriate safeguards.

We do not sell personal data or Google user data.

7. Cookies and browser storage

The public Fidkeep marketing website is static and, at the effective date of this policy, does not use analytics, advertising pixels, or marketing cookies. The authenticated application uses strictly necessary, same-origin cookies to maintain secure sessions. Session cookies are configured as HttpOnly so browser scripts cannot read the session token.

The application may use limited browser storage for user-interface preferences, such as theme or recently used sign-in choices. Disabling necessary cookies may prevent account sign-in or protected service functions from working.

8. Data retention, revocation, and deletion

We retain account and workspace data while your account or customer relationship is active and for as long as reasonably necessary to provide the service. Google OAuth tokens are retained while the account remains linked or while needed to provide authorized background access. Review, reply, report, audit, delivery, and operation records may remain for continuity, security, dispute resolution, legal compliance, and protection against duplicate or unauthorized actions.

You may request deletion of your account or specific stored data by emailing [email protected]. We may need to verify your identity and authority over the relevant workspace. Some information may be retained where deletion would conflict with legal obligations, the rights of other workspace members, fraud prevention, security, or the integrity of immutable operational records. Residual copies may remain temporarily in protected backups until they are overwritten under normal backup procedures.

9. Security

We use administrative, technical, and organizational safeguards intended to protect data, including encrypted Google OAuth tokens, protected password storage, HttpOnly session cookies, transport encryption, role and location-based access controls, redacted audit records, secret management, request validation, and restricted operational endpoints.

No internet service is completely secure. You are responsible for protecting account credentials, using appropriate access roles, and notifying us promptly if you suspect unauthorized access.

10. Your choices and rights

Subject to applicable law, you may have rights to access, correct, obtain a copy of, restrict, object to the processing of, or request deletion of personal data. You may also withdraw consent and complain to an applicable data protection authority.

You can update certain profile and workspace information in the application, revoke Google access in your Google Account, or contact [email protected]. We may request information needed to verify your identity, authority, and the scope of the request.

11. International data transfers

Google, OpenRouter, model providers, Linear, Resend, and infrastructure providers may process data in countries other than the country where you live. Where required, we rely on contractual, legal, or other recognized safeguards for international transfers and limit disclosure to what is needed for the relevant service.

12. Children

Fidkeep is a business service and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. If you believe a child has provided personal data to Fidkeep, contact us so we can investigate and take appropriate action.

13. Changes and contact

We may update this policy when the service, providers, or legal requirements change. We will post the updated version here and revise the effective date. If a change materially affects how we use data, we will provide additional notice where required.

For privacy questions, requests, or complaints, contact Fidkeep at [email protected]. You can also review our Terms of Service.

Fidkeep

Manage Google reviews, prepare replies in your brand voice, and follow location performance.

Product

FeaturesHow it works

Legal

Privacy PolicyTerms of Service

Contact

[email protected]

© 2026 Fidkeep. All rights reserved.

Google Business Profile is a trademark of Google LLC.